Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966

 

Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966

Published: January 17, 2023 / Updated: February 8, 2023


Vulnerability identifier: #VU71210
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-47966
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to unspecified error in the Apache Santuario, which affects Zoho ManageEngine products, when SAML SSO is enabled. A remote non-authenticated attacker can bypass authentication process and compromise the affected system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apache Santuario XML Security for Java
ManageEngine Access Manager Plus
Zoho ManageEngine Active Directory 360
OS Deployer
Remote Monitoring and Management (RMM)
Zoho ManageEngine ADAudit Plus
Endpoint DLP
Patch Manager Plus
Vulnerability Manager Plus
Device Control Plus
ManageEngine Application Control Plus
Endpoint Central
Endpoint Central MSP
ManageEngine Browser Security Plus
ManageEngine Analytics Plus
PAM 360
Key Manager Plus
Password Manager Pro
Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine Remote Access Plus
Zoho ManageEngine ServiceDesk Plus
ManageEngine AssetExplorer
Zoho ManageEngine ADSelfService Plus
Zoho ManageEngine ADManager Plus
Zoho ManageEngine SupportCenter Plus

How to mitigate CVE-2022-47966

Install updates from vendor's website.

Apache Santuario XML Security for Java - addressed in versions 2.3.2, 3.0.1
ManageEngine Access Manager Plus - update to 4.3 4308
OS Deployer - update to 1.1.2243.1
Remote Monitoring and Management (RMM) - update to 10.1.41
Endpoint DLP - update to 10.1.2137.6
Patch Manager Plus - update to 10.1.2220.18
Vulnerability Manager Plus - update to 10.1.2220.18
Device Control Plus - update to 10.1.2220.18
ManageEngine Application Control Plus - update to 10.1.2220.18
Endpoint Central - update to 10.1.2228.11
Zoho ManageEngine Remote Access Plus - update to 10.1.2228.11
Endpoint Central MSP - update to 10.1.2228.11
ManageEngine Browser Security Plus - update to 11.1.2238.6
Zoho ManageEngine ServiceDesk Plus - update to 14.0 14004
Zoho ManageEngine Active Directory 360 - update to 4310
ManageEngine Analytics Plus - update to 5150
PAM 360 - update to 5713
Zoho ManageEngine ADSelfService Plus - update to 6211
Key Manager Plus - update to 6401
ManageEngine AssetExplorer - update to 6983
Zoho ManageEngine ADAudit Plus - update to 7081
Zoho ManageEngine ADManager Plus - update to 7162
Zoho ManageEngine SupportCenter Plus - update to 11026
Password Manager Pro - update to 12124
Zoho ManageEngine ServiceDesk Plus MSP - update to 13001

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins